Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Park n Spam

    Aug16
    9:40 am (UTC-7)   |    by

    Parked domains are basically domain names currently not in use, meaning, there is no actual web site related to the domain. Domain parking happens when an entity buys a domain name, but does not have a web site ready yet (can also be a form of typo-squatting).


    In this case, the domain name owner can contact a domain parking company that will use his domain name to serve advertisement. The domain name owner is paid according to the number of visits in the parked domain. Recently, ScanSafe discovered several parked domains that not only serve advertisements, but also malware! The malicious file, it seems, is downloaded from the domain smalltool.net. The downloaded file, setup.exe, seems to be target German users, based on the fake EULA shown by the file when executed.


    setup-cchost.JPG


    Setup.exe then installs cchost.exe on the C:Program Filescchost folder, together with the “uninstall” file unins000.exe and the data file unins000.dat. When unins000.exe is executed, it deletes itself and unins000.dat, but leaves the cchost.exe behind.


    All files mentioned are detected as TROJ_SMALL.ITG. Cchost.exe is the main malware file that connects to smalltool.net to retrieve commands. A description by Kaspersky reveals that smalltool.net is a spam domain, serving e-mail addresses and spam messages to machines infected by TROJ_SMALL.ITG, effectively making them spam zombies. As of writing, smalltool.net is not yet giving commands to cchost.exe to spam. Maybe it’s just waiting for the right time?





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice